Skip to content

GHSA/SYNC: 1 new faraday advisory - #1058

Merged
flavorjones merged 1 commit into
rubysec:masterfrom
jasnow:ghsa-syncbot-2026-05-19-20_33_30
May 27, 2026
Merged

GHSA/SYNC: 1 new faraday advisory#1058
flavorjones merged 1 commit into
rubysec:masterfrom
jasnow:ghsa-syncbot-2026-05-19-20_33_30

Conversation

@jasnow

@jasnow jasnow commented May 20, 2026

Copy link
Copy Markdown
Member

GHSA/SYNC: 1 new faraday advisory

Comment thread gems/faraday/CVE-2026-33637.yml
unaffected_versions:
- "< 2.0.0"
patched_versions:
- ">= 2.14.2"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

https://nvd.nist.gov/vuln/detail/CVE-2026-33637 says

This issue has been fixed in version 2.14.3.

But there is no 2.14.3 :-o https://rubygems.org/gems/faraday/versions. So something is off in here. Is CVE wrong? Should we report?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, nvd website data is wrong so I did not use it. Check the release notes URL.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unclicked "Resolve comment" button - will wait for your feedback.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All good, just wondering if there's known contact where to report such a mistakes.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, nvd website data is wrong so I did not use it. Check the release notes URL.

Try GitHub Security Advisory (GHSA) web site - see that NVD website got the data from there.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If you want to fix this data, this can be worked separately from this PR.

@flavorjones flavorjones left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This version information matches the GHSA and the release notes, so I'm going to merge it.

@flavorjones
flavorjones merged commit f6f8da4 into rubysec:master May 27, 2026
1 check passed
@jasnow
jasnow deleted the ghsa-syncbot-2026-05-19-20_33_30 branch May 27, 2026 12:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants